Security
Security at Noer
We take security seriously and aim to build Noer with practical protections across accounts, billing, infrastructure, and platform operations.
Security is an ongoing process. As the ecosystem grows, our practices, controls, and internal processes will continue to evolve with it.
Our security approach
Noer is being built as a shared platform for multiple AI products. That means security is not treated as a single feature inside one app, but as a cross-platform concern that affects identity, billing, infrastructure, AI workflows, and product operations.
We focus on practical, layered protections and sensible operational defaults rather than making exaggerated claims. No service can promise absolute security, but we work to reduce risk and improve resilience over time.
For information about privacy and data handling, please also review our Privacy Policy.
Security highlights
Encrypted transport
We use HTTPS and standard transport protections for traffic to supported services.
Third-party payment handling
Payment information is handled by dedicated payment processors, not stored directly by us.
Monitoring and controls
We use operational monitoring, logging, and service-level controls to support reliability and abuse response.
Platform-oriented design
Shared systems such as identity and billing are designed to support multiple products across the ecosystem.
Security areas
Key parts of the platform security model
Account security
We use standard security practices for authentication, session handling, access control, and account-related protections.
- Secure authentication flows
- Password reset and account verification flows
- Session and cookie protections
- Least-privilege access patterns where applicable
Payment security
Payments are processed by third-party providers such as Paddle. Noer does not store payment card details on its own servers.
- Third-party payment processing
- No direct card storage on Noer infrastructure
- Billing handled through dedicated payment systems
Infrastructure security
We design the platform with security-minded deployment and operational practices across hosting, networking, monitoring, and service configuration.
- HTTPS and encrypted transport
- Environment-based secret handling
- Operational monitoring and logging
- Backups and infrastructure controls through cloud providers
Abuse prevention
We apply platform controls to reduce abuse, misuse, and attempts to disrupt systems or bypass safeguards.
- Rate limiting and traffic controls where appropriate
- Abuse detection and service monitoring
- Account or workflow restrictions for policy violations
- Review and response to reported misuse
Responsible disclosure
If you believe you have found a security issue affecting Noer, please report it responsibly and include as much relevant detail as possible.
Helpful reports usually include a description of the issue, affected page or workflow, reproduction steps, and any supporting context that helps us investigate safely.
Please do not attempt destructive testing, social engineering, data access, service disruption, or any activity that could harm users, systems, or third parties.
Security contact
For security-related questions or responsible disclosure, contact:
For general platform and data questions, see also the FAQ and Privacy Policy.